You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Added built-in slskd support across Launcharr's downloader catalog, dashboard queue views, widget stats, and app settings.
Added configurable per-dashboard auto-refresh so supported overview modules and queues can refresh without a full page reload.
Tightened CSRF coverage for login/setup flows and runtime-generated settings forms to prevent legitimate admin actions from failing server-side validation.
Added
Added built-in slskd metadata in config/default-apps.json, including icon wiring and downloader categorization, plus app settings support for API key or username/password access.
Added public/dashboard-refresh.js and dashboard-level refresh settings in src/views/settings.ejs so each dashboard can opt into a 15-3600 second refresh interval.
Added refresh hooks across supported overview/queue frontends so Arr, media, downloader, and specialty cards can reuse the same dashboard refresh event instead of each page needing a hard reload.
Fixed
Fixed CSRF coverage gaps across local login/setup forms, Plex PIN registration requests, and JavaScript-created settings POST forms. This resolves cases where valid actions, including dashboard item removal, could land on a plain CSRF validation failed. screen.
Fixed dashboard and app-overview downloader queues to recognize slskd items, map Soulseek-specific statuses, and render the correct user/detail labels in both dedicated and combined queue tables.
Fixed reverse-proxy auth guidance and secure-cookie defaults so docs now match the hardened runtime behavior around TRUST_PROXY and COOKIE_SECURE.
Changed
Raised the minimum local password length from 6 to 12 characters.
Updated dashboard runtime wiring so refresh-enabled dashboards emit a shared refresh event on interval and on tab visibility restore, reducing the need for duplicate per-module timers.
Updated downloader integrations/docs to list slskd alongside the existing Transmission/qBittorrent/SABnzbd/NZBGet support.
Upgrade Notes
No schema migration is required. Update and restart Launcharr.
Existing dashboards keep auto-refresh disabled until you enable it in Settings -> Custom -> Dashboard.
If Launcharr is behind a reverse proxy terminating HTTPS, set TRUST_PROXY=true (and TRUST_PROXY_HOPS as needed). Leave COOKIE_SECURE unset in production unless you need an explicit override.
Local-auth setups must now use passwords with a minimum length of 12 characters for new setup/user password changes.